Free cyber tool

SMB1001 self-assessment

Answer five quick questions about your business and get an indicative SMB1001 tier readiness, plus exactly what to fix in each control area to reach the next tier.

Indicative only, takes about two minutes

SMB1001 is the Australian cyber security standard for small and medium businesses, maintained by Dynamic Standards International. It organises its controls into five areas, and certification at a tier means meeting that tier across all five. Your readiness is therefore set by your weakest area, so this tool scores each one and shows where you stand.

Question 1 of 5
1 Technology Management

How are your devices, operating systems and applications kept current and securely configured?

2 Access Management

How is access to your systems controlled, and where is multi-factor authentication enforced?

3 Backup & Recovery

How are your backups run, protected from ransomware, and proven to actually restore?

4 Policies & Processes

What security policies, incident response and supplier requirements do you have documented?

5 Education & Training

What security awareness training do your staff actually receive?

What is SMB1001?

SMB1001 is an Australian cyber security standard written specifically for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. Where frameworks like ISO 27001 assume a dedicated security function and a budget to match, SMB1001 was built for businesses of roughly 5 to 200 staff, and it certifies in progressive tiers so a smaller business can reach a real, usable outcome without a two-year programme.

It also aligns deliberately with the ACSC Essential Eight, the UK's Cyber Essentials scheme and elements of the US CMMC, which is why it works as a stepping stone toward ISO 27001 rather than a dead end. This free tool gives you an indicative tier readiness in about two minutes, with no sign-up.

The five control areas

SMB1001 organises its controls into five coverage areas. Certification at a tier means meeting that tier's requirements across all five, which is why your readiness is set by your weakest area rather than your average.

The SMB1001 tiers explained

There are five progressive tiers. The important distinction for planning is where independent assessment begins.

Why SMB1001 matters for South Australian businesses

Cyber security questions have moved into procurement. Larger clients ask suppliers to demonstrate a security posture, insurers ask at renewal, and government-adjacent work increasingly expects something more than a verbal assurance. For a business of 20 or 50 people, ISO 27001 is often disproportionate, and an Essential Eight maturity score is useful internally but harder to hand to a client as evidence. SMB1001 produces a shareable certificate and digital badge, which is a concrete answer to a procurement question.

We are ISO 27001 certified ourselves, so the evidence discipline SMB1001 asks for is how we already work rather than something we advise on from a distance.

How this self-assessment works

You answer one question per control area, choosing the option that best describes where you genuinely are today. Each answer maps to a readiness band, and your overall indicative tier is the lowest band across the five areas, mirroring how tiered certification actually works. The breakdown then shows, for each area, the specific step that would lift it to the next tier.

This is indicative only. It is based on a single question per control area and verifies no evidence, so treat it as a way to see roughly where you stand before committing to a formal gap analysis. A real gap analysis tests each control against the full standard and, crucially, tests whether your evidence would satisfy an assessor.

Frequently asked questions